Description
Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication.
No analysis available yet.
Remediation
Vendor Solution
Contact tech support from Chain Sea Information Integration Co., Ltd
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31013 | Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attacker to perform JavaScript injection for XSS (reflected Cross-site scripting) attack without authentication. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5399-03b81-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:43:57.373Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44163
No data.
Status : Modified
Published: 2021-12-20T03:15:06.770
Modified: 2024-11-21T06:30:28.650
Link: CVE-2021-44163
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD